Terminology Index

Glossary

2953 terms

Open concept maps
B
32

Baseline Analysis

Establishing what normal activity looks like in an environment so that deviations stand out as worth investigating. In detection and SIEM work, the baseline is the reference against which anomalies are measured.

Many detections depend on knowing normal, typical login times, common processes, usual network volumes, because attacks often appear as departures from it. Building and maintaining baselines lets analysts spot first-seen or rare events and tune detections so they alert on the genuinely unusual.

Introduced in: SIEM Query Fundamentals

Examples

  • Learning a server's normal outbound traffic so a spike stands out.
  • Baselining which processes commonly run so a new one is noticeable.
  • Establishing typical login hours to flag off-hours access.